Skip to main content

To-Do Controls

Controls that are not yet implemented or only partially addressed. These require development work (platform) or policy/procedure creation (operator) before the control is satisfied.

24 controls with this tag.

IDTitleStatusOwnerCSF Function
SID-DATA-06PII Field Encryption for User Recordsto_doplatformprotect
SID-ORG-01Information Security Policyto_dooperatorgovern
SID-ORG-02Roles, Responsibilities, and Segregation of Dutiesto_dooperatorgovern
SID-ORG-03Risk Management Frameworkto_dooperatoridentify
SID-ORG-04Supplier and Third-Party Securityto_dooperatorgovern
SID-ORG-05Legal, Regulatory, and Contractual Complianceto_dooperatorgovern
SID-ORG-06Wallet Service Practice Statementto_dooperatorgovern
SID-ORG-07Terms of Service and Privacy Policyto_dooperatorgovern
SID-KEY-03FIDO WSCD via Sign Extension (previewSign)to_doplatformprotect
SID-OPS-01Incident Response and Managementto_dooperatorrespond
SID-OPS-02Business Continuity and ICT Readinessto_dooperatorrecover
SID-OPS-03Backup and Recoveryto_dooperatorrecover
SID-OPS-04Vulnerability Managementto_doplatformdetect
SID-OPS-05Change Managementto_doplatformgovern
SID-OPS-06Monitoring and Alertingto_dooperatordetect
SID-OPS-07Fraud Managementto_dooperatordetect
SID-OPS-08Secure Development Lifecycleto_doplatformprotect
SID-PPL-01Personnel Screening and Onboardingto_dooperatorprotect
SID-PPL-02Security Awareness, Education, and Trainingto_dooperatorprotect
SID-PPL-03Confidentiality and Non-Disclosure Agreementsto_dooperatorprotect
SID-PPL-04Information Security Event Reportingto_dooperatordetect
SID-PHY-01Data Center Physical Securityto_dooperatorprotect
SID-PHY-02Equipment and Media Securityto_dooperatorprotect
SID-PRIV-03Right-to-Erasure Bulk Deletion APIto_doplatformprotect